Search CVE reports


Toggle filters

81 – 90 of 49529 results

Status is adjusted based on your filters.


CVE-2026-15109

Medium priority
Needs evaluation

security update

6 affected packages

chromium-browser, webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
chromium-browser Not affected
webkitgtk Not in release
webkit2gtk Needs evaluation
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-105221

Medium priority
Needs evaluation

(The gist RubyGem before 6.1.0 contains an improper certificate validat ...)

1 affected package

gist

Package 24.04 LTS
gist Needs evaluation
Show less packages

CVE-2026-105083

Medium priority
Needs evaluation

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the...

1 affected package

imagemagick

Package 24.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-104988

Medium priority

Not in release

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The...

1 affected package

dogtag-pki

Package 24.04 LTS
dogtag-pki Not in release
Show less packages

CVE-2026-104874

Medium priority
Needs evaluation

Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation,...

1 affected package

python-multidict

Package 24.04 LTS
python-multidict Needs evaluation
Show less packages

CVE-2026-104855

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invalid intermediate state when an...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-104851

Medium priority
Needs evaluation

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents...

1 affected package

fsspec

Package 24.04 LTS
fsspec Needs evaluation
Show less packages

CVE-2026-104843

Medium priority

Not in release

uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including...

2 affected packages

uv, uv-full

Package 24.04 LTS
uv Not in release
uv-full Not in release
Show less packages

CVE-2026-104733

Medium priority
Needs evaluation

User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.

1 affected package

ejabberd

Package 24.04 LTS
ejabberd Needs evaluation
Show less packages

CVE-2026-104721

Medium priority
Needs evaluation

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender...

1 affected package

logback

Package 24.04 LTS
logback Needs evaluation
Show less packages